Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 216.21.168.27. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:216.21.168.27
Hostname:216-21-168-27.mci.googlefiber.net
Status:Offline
Spamhaus SBL:SBL410482
Malware:Heodo -
AS number:AS16591
AS name:GOOGLE-FIBER - Google Fiber Inc.
Country:- US
First seen:2018-06-19 14:50:43 UTC
Last seen:2019-01-13 14:56:12 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-02-26 02:28:54dd9c6a355b5c22e4b5c4399dc2b67d3aVirustotal results 48/71 (67.61%) 216.21.168.2753Heodo
2019-01-09 02:05:18f2d2ea706db6c4c7d6f7e885d08e8a09Virustotal results 53/69 (76.81%) 216.21.168.2753Heodo
2019-01-08 17:58:372459bb3271c3d45d1c4caf1f325913e8Virustotal results 51/68 (75.00%) 216.21.168.2753Heodo
2019-01-08 15:14:34e859f8e369758e85dcf51aa55857aaa2Virustotal results 50/68 (73.53%) 216.21.168.2753Heodo
2019-01-08 14:38:46d98bb4bb1a0022625ddb434a0e1393fcVirustotal results 48/70 (68.57%) 216.21.168.2753Heodo
2019-01-08 13:29:1290d385795229c4dfe8f0d060776cec5fVirustotal results 53/70 (75.71%) 216.21.168.2753Heodo
2019-01-08 12:41:20e15c25c95fcdf67cab2c45a550d44183Virustotal results 51/68 (75.00%) 216.21.168.2753Heodo
2019-01-08 11:18:5719749b568da173087a3aeaf9f3f79b1cVirustotal results 53/68 (77.94%) 216.21.168.2753Heodo
2019-01-08 08:12:35b539c8e76d8354574f7807caa800fa4bVirustotal results 52/69 (75.36%) 216.21.168.2753Heodo
2019-01-08 07:40:1203f30e9c3014c63b46eb077c8349b435Virustotal results 47/68 (69.12%) 216.21.168.2753Heodo
2018-12-03 05:01:5001d9f2f47e617591217b60eb5a62fd62Virustotal results 44/68 (64.71%) 216.21.168.2753Heodo
2018-11-12 07:09:59182bf9f677220670b7f19ced80758a73Virustotal results 39/60 (65.00%) 216.21.168.2753Heodo

# of malware samples: 12